Exactly where the message exists.
PlugMail separates the active delivery copy, your durable local copy, and a short-lived encrypted recovery copy. “Deleted” means logically and cryptographically inaccessible through the service; we do not market fictional per-file SSD overwrites.
The custody handoff
Deletion follows proof, not a timer guess.
- 01receive
PlugMail accepts the full message into the temporary delivery queue.
- 02commit
The primary device verifies the MIME hash and commits it into the encrypted local vault.
- 03acknowledge
The device signs a nonce-bound local-commit acknowledgement.
- 04purge
The active server copy is removed; an encrypted recovery copy expires within 72 hours.
local 94server 2recovery 4
Free
- Maximum 100 unsynchronized server messages.
- Unsynchronized messages are not silently deleted after 72 hours.
- Active copy leaves after verified local commit.
- Encrypted recovery copy expires no later than 72 hours after acknowledgement.
- Local storage is bounded by your device.
Premium
- Pull & Purge remains available.
- Optional persistent private cloud vault, encrypted for the user.
- “Unlimited” means no fixed mailbox-message quota, subject to fair use and platform capacity.
- Persistent mode is opt-in and visibly different from Pull & Purge.
Loss model: after the 72-hour recovery copy expires, PlugMail cannot recover a message that was deleted from every registered local backup. The client must make this visible before activation.